Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

OAuth Authentication Decisions Not Logged

Đang mở
#91 1 bình luận 0 reaction 1 người được giao Xem trên GitHub

@sbp đang làm issue này rồi.

Từ ngày 24/4/2026.

Đánh giá

Issue này chưa được đánh giá.

Mô tả

ASVS documentation

Issue: FINDING-135 - OAuth Authentication Decisions Not Logged

Labels: bug, security, priority:medium, asvs-level:L1

ASVS Level(s): [L1]

Description:

Summary

The OAuth authentication callback handler (/auth endpoint) makes critical authentication decisions but does not log any of them. Both successful logins and failures (invalid/expired state, OAuth provider rejection) occur silently. OAuth is the primary web authentication mechanism, making this a significant gap. The code validates state tokens, calls OAuth providers, and creates sessions without any audit trail, preventing detection of state token brute-force, replay attacks, or compromised accounts.

Details

Affected locations:

  • src/asfquart/generics.py lines 83-109: OAuth callback without logging
  • src/asfquart/generics.py lines 52-115: Authentication flow without audit

The OAuth callback performs authentication but never logs success or failure, creating complete gap in audit trail for primary web authentication mechanism.

Recommended Remediation

Implement an after_request hook to capture OAuth authentication decisions. In atr/server.py, add @app.after_request handler that checks if request.path == '/auth' and logs oauth_login_success (status 200 with uid) or oauth_login_failure (status 403):

@app.after_request
async def log_oauth_decisions(response: quart.Response) -> quart.Response:
    """Log OAuth authentication decisions for audit trail."""
    if quart.request.path == '/auth':
        if response.status_code == 200:
            # Successful login - extract uid from session
            session_data = await asfquart.session.read()
            log.info('oauth_login_success', extra={
                'asf_uid': session_data.get('uid'),
                'remote_addr': quart.request.remote_addr
            })
        elif response.status_code in (403, 401):
            # Failed login
            log.warning('oauth_login_failure', extra={
                'state_token': quart.request.args.get('state', '')[:8] + '...',  # Truncated
                'remote_addr': quart.request.remote_addr,
                'status': response.status_code
            })
    return response

Include asf_uid for success cases and failure reason for rejection cases.

Acceptance Criteria
  • OAuth authentication success is logged
  • OAuth authentication failure is logged
  • Log entries include user identity and remote address
  • Audit trail is complete for OAuth flow
  • Test cases verify OAuth logging
  • Unit test verifying the fix
References
  • Source reports: L1:7.2.2.md
  • Related findings: FINDING-134, FINDING-136, FINDING-250
  • ASVS sections: 7.2.2
Priority

Medium

Ngôn ngữ chính
Python
Star
7
Fork
13
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Chuẩn bị môi trường

Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của apache/infrastructure-asfquart

Tất cả issue của apache/infrastructure-asfquart

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.